Sophos

Troj/Lineage-V

Aliases
  • Trojan-PSW.Win32.Lineage.eu
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2005 (3.96)
Protection available since 30 June 2005 06:37:10 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Lineage-V is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the game called "Lineage".

Troj/Lineage-V includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Lineage-V copies itself to <Windows>\svchost.exe and creates the file <System>\user.txt. User.txt is a data file with collected information which will be sent to remote a remote user via email.

The following registry entry is created to run svchost.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KAVPersonal
<Windows>\svchost.exe

Troj/Lineage-V searches for the "Lineage","Lineage Windows Client" window in attempt to initiate a keylogging routine. The Trojan records keypresses to a data file and can send the data file to a remote user through email.

Troj/Lineage-V may delete all files with the following extensions from the <Windows>\Media folder:

wav
rmi
mid

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer